Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.49%—Star-citizen EmbedvideoAI15/9/202630/9/2026
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown…
AplazadaAlta (7.7)0.28%—Suprema Biostar XAISupremainc Biostar 2AI14/9/202622/9/2026
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
AplazadaMedia (5.3)0.33%—Starlette-adminAI12/9/202623/9/2026
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison…
AplazadaMedia (4.3)0.25%—Starter TemplatesAI11/9/202611/9/2026
Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.
AplazadaBaja (2.1)0.37%—Starcounter-jack Json-patchAI8/9/202628/9/2026
A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation…
AplazadaMedia (5.5)0.76%—Starcounter-jack Json-patchAI7/9/20268/9/2026
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The…
AplazadaMedia (6.9)0.41%—Lightstar Smartit Desktop ManagerAILightstar Smartit AgentAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
AplazadaCrítica (9.3)0.63%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
AplazadaAlta (8.7)0.33%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
AplazadaCrítica (9.3)0.63%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
Pendiente de análisisAlta (8.7)0.32%—Armorstart LTAI1/9/20261/9/2026
A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability
Pendiente de análisisMedia (6.9)0.28%—Armorstart LTAI1/9/20261/9/2026
Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.
AplazadaBaja (1.3)0.31%—Lognet Grpc-spring-boot-starterAI31/8/202631/8/2026
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability…
AplazadaMedia (6.5)0.55%—StarrocksAI28/8/202623/9/2026
StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including…
AplazadaMedia (5.3)0.38%—StarrocksAI28/8/202623/9/2026
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints on the frontend HTTP port to disclose cluster topology, database metadata, JVM…
AplazadaMedia (4.3)0.30%—Wgstart WgcloudAI26/8/202631/8/2026
An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.
AplazadaMedia (5.4)0.45%—Starlette AdminAITiangolo FastapiAIEncode StarletteAI26/8/20269/9/2026
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlists. An…
AplazadaAlta (7.1)0.53%—StarrocksAI26/8/202623/9/2026
StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement returns immediately with a comment stating the check happens in execution logic.…
AplazadaAlta (7.7)0.24%—HP Easy StartAI24/8/20263/9/2026
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
AplazadaAlta (7.7)0.36%—HP Easy StartAI24/8/20263/9/2026
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
AplazadaAlta (8.5)0.30%—HP Easy StartAI24/8/20263/9/2026
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
AplazadaMedia (5.3)0.52%—Kamalkhan KK Star RatingsAI22/8/202626/8/2026
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running…
AplazadaAlta (7.5)0.46%—Kadencewp Starter TemplatesAI18/8/202620/8/2026
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
AplazadaBaja (2.1)0.35%—Spacex Starlink Router GEN 3AI16/8/202620/8/2026
A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the…
AplazadaMedia (5.3)0.16%—Fivestarplugins Five Star Restaurant ReservationsAI6/8/202626/8/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending…